RRAS穿越Firewall用NAT提供安全性上网

限时加码!20+主流AI编程工具免费用 购周边加赠Coding Plan Lite,Claude Code、Cursor等即刻畅享,学习进阶更高效! 阅读详情
QUESTION NO: 150
You are the administrator of TestKing’s network, which consist of a single Windows 2000 domain. The relevant portion of its configuration is shown in the exhibit.

RAS1 is a Windows 2000 Server computer running routing and remote access. Your firewall is a hardware-based firewall solution that supports port filtering and General routing Encapsulation packet editing. All computers on your internal subnet use private IP addresses in the 10xxx range. The firewall provides network address translation for Internet access. Company employees must be able to use the Internet to connect to your internal subnet. You need to ensure that the connections are as secure as possible.
Which three courses of action should you perform? (Each correct answer presents part of the solution. Choose three)

A. Configure the client computers to dial in to RAS1 by using an L2TP virtual private network. Configure RAS1 to accept L2TP connections.
B. Configure the client computers to dial in to RAS1 by using a PPTP virtual private network. Configure RAS1 to accept PPTP connections.
C. Configure the firewall to route incoming traffic on the PPTP port to RAS1
D. Configure the firewall to route incoming traffic on the L2TP port to RAS1
E. Configure the firewall to edit the GRE call ID on incoming GRE packets
F. Install a server encryption certificate on RAS1

Answer: B, C, E

Explanation:
B: The firewall provides network address translation. This makes it impossible to use L2TP/IPSec since IPSEC changes the IP headers. We cannot use the L2TP protocol since it would not provide any security, which is a requirement. So the clients and the RAS server must be configured to use PPTP.
C: PPTP use port 1723 for maintenance traffic. Incoming traffic in this port should be routed to RAS1.
E: If we are using a PPTP tunnel, then we can place our VPN server behind the firewall if the firewall supports GRE packet editing, which is the case in this scenario. Unlike the TCP and IP protocols, which communicate on ports, the GRE protocol uses "call ID numbers" to establish sessions.

Reference: Technet: VPNs and Network Address Translators

Incorrect Answers:
A: L2TP/IPSEC cannot be used in connection with NAT.
D: There are no L2TP ports to be configured on the firewall. We must use PPTP not L2TP or L2TP/IPSec.
F: PPTP includes encrypted tunneling. Installing a server encryption certificate would not improve the
encryption of the tunnel.
【图像大模型】RIFE实战:如何通过中间流估计实现4K视频的实时插帧优化 本文深入解析了基于深度学习的RIFE视频插帧算法,重点探讨其核心的中间流估计技术如何实现高效精准的帧生成。通过实战教程,详细介绍了针对4K视频的实时处理优化方案,包括环境配置、参数调优及性能瓶颈分析,帮助用户利用消费级显卡将低帧率视频转化为流畅的高帧率体验。 阅读详情

相关推荐

Ollama-OCR实战:5分钟搞定PDF文档转Markdown(附qwen2.5vl模型配置)

本文详细介绍了如何利用Ollama本地部署多模态大模型qwen2.5vl,结合OCR技术,实现PDF文档到Markdown的端到端智能转换。通过解析传统OCR的局限与AI方案的优势,并提供从环境搭建、提示词工程到处理复杂表格的完整实战指南,帮助用户高效构建自动化文档处理流水线,彻底重塑文档处理工作流。

yog99的博客 580

Windows 网络地址转换(NAT)服务全解析

Windows 网络地址转换(NAT)服务在当今网络环境中具有极其重要的地位与广泛的应用价值。它通过巧妙的 IP 地址转换、端口转换以及网络地址转换等功能,有效地解决了 IPv4 地址资源紧张的难题,使得众多内部网络设备能够借助有限的公共 IP 地址畅游互联网。无论是家庭网络中的多设备共享上网,还是企业网络内的资源交互与安全防护,亦或是公共场所的无线网络服务,NAT 服务都展现出了其不可或缺的作用。

CSY20230308003的博客 1571

Antlr4入门(二)基本概念解析

在上一章中(Antlr4入门(一)IDEA中Antlr的安装与使用),我们安装了Antlr,并编写运行了第一个程序“Hello world”。而在本章中,我们将学习语言类应用程序相关的重要过程、术语和数据结构。 一. 术语 语言(language)是由一系列有意义的语句组成,语句(sentence)由词组组成,词组(phrase)是由更小的子词组(subphrase)和词汇符号(vocabulary symbols)组成。 举个例子,英语就是一种语言,“Keep on going never gi.

qq_37771475的博客 5190

Hyper-V, ICS, RRAS NAT and port-forwarding on Windows Server 2012

Installing and Configuring Network Address Translation (NAT) on your Host Computer to connect Virtual Machines running on an internal Hyper-V Virtual Switch   If you are running your virtual machin...

changandaxue的专栏 286

ubuntu ufw nat 内网代理上网

ubuntu ufw nat 内网代理上网为什么使用ubuntu ufw nat系统换Linux Ubuntu添加更复杂的控制语句做代理 为什么使用ubuntu ufw nat 很多原因吧,其中之一是因为isa(tmg)在server2008以上不好科学使用 系统换Linux Ubuntu 开源,免费,安装简单,自带ufw(iptables的简化版,晚于iptables级别)。 比如: ufw e...

sflsgfs的专栏 1583

windows server2008 配置RRAS服务器

环境:本地局域网主机、路由与远程访问服务器、远端局域网   拓扑: 方案: 第一,可以将一个配置过的RRAS作为两个子网间转换数据的IP路由。这样做,测试网络中的客户可以将数据包发送到互联网上的服务器,但是却不能让数据回流到客户。原因是从互联网出来的数据会被发送到地址为192.168.1.0的网络,因此数据无法到达地址为10.1.1.0的网络。解决这一问题的一贯做法是为直接转发数据

gr23344的专栏 1万+

路由器的工作原理

路由器的工作原理  我们知道路由器是用来连接不同网段或网络的,在一个局域网中,如果不需与外界网络进行通信的话,内部网络的各工作站都能识别其它各节点,完全可以通过交换机就可以实现目的发送,根本用不上路由器来记忆局域网的各节点MAC地址。路由器识别不同网络的方法是通过识别不同网络的网络ID号进行的,所以为了保证路由成功,每个网络都必须有一个唯一的网络编号。路由器要识别另一个网络,首先要识别的就是对

技术日志 7235

Event ID: 30013 The DHCP allocator has disabled itself

Event ID: 30013Sourceipnathlp TypeError DescriptionThe DHCP allocator has disabled itself on IP address 169.254.236.250, since the IP address is outside the 192.168.0.0/255.255.255.0 scope from which

技术日志 4850

VMware网桥连接方式

网桥方式主机为2000Server 192.168.1.2VPC1为2000pro 192.168.1.3VPC2为2000Server 192.168.1.4VMware 4.5.2设置: 取消自动桥接,主机虚拟网络查看中选定192.168.1.2的网卡.主机VMware服务全禁.真实网卡-属性-协议-Bridge打勾.(只有这里打勾,VMware主机虚拟网络查看中才可看到)

技术日志 3914

eventID 20106 来源 RemoteAccess

当开启了ICS或NAT, 而没有客户机时, 就会出现此信息. 好像不可避免.

技术日志 3222

安装及配置RRAS的条件

安装及配置路由及远程访问的条件2000 Srv and above远程注册表服务 -注意这条,如果服务里此项设为禁用或手动,均导致路由和远程访问无法正常打开!RRAS服务

技术日志 2217

关于ICS,Internet连接共享

ICSInternet Connection Sharing通过在使用拨号连接的计算机上启用 Internet 连接共享,您可以为家庭网络中的所有计算机提供网络地址翻译、寻址和名称解析服务。其中包含有一个Mini-DHCP当启用了ICS,也就启用了一个Mini-DHCP Server, 它包括DHCP allocator, DNS proxy 及 WINS proxy组件.不能将ICS与DHCP用

技术日志 2214

远程用户不能获得正确的DHCP作用域选项

QUESTION NO: 133You are the administrator of a Windows 2000 network. The network consists of a Windows 2000 based DHCP server, two Windows 2000 based DNS server, a Windows 2000 based routing and remot

技术日志 2002

Event ID 407, 408 - 当NAT用作DNS服务器时...

QUESTION NO: 211You are the administrator of TestKing’s network, which consists of a single Windows 2000 Domain. Therelevant portion of its configuration is shown in the exhibit.You configure a Window

技术日志 1977

VMware测试路由

用VMware 4.5.2,主机虚拟网络只能和主机通信. 但通过添加额外的软件支持就可做到Internet或不同网络间相互访问.例:主机启动RRAS做路由(这里测试的是2000 RRAS-网络路由器), 另用2个虚拟机做虚拟主机网络主机: Win2000 Server                  VMnet2: IP 192.168.9.1/25                 VMnet8

技术日志 1963

NAT心得

如果不想用NAT上的dhcp,又不想配置, 则可在服务器内网网卡上指定地址为:169.254.0.1 ,Netmask为255.255.0.0, 客户机用APIPA即可上网了. 注意这里一定要用地址范围的第一个IP.灵活运用APIPA有时可省去不少配置.ICS是NAT的简化版,原理一样. 当用向导配置后,其内网都是没有默认网关的, 其实就是外网的IP地址. 个人感觉在这里, 内网卡与外网卡又自成一

技术日志 1961

判断如何添加静态路由

QUESTION NO: 242You are the network administrator for TestKing. TestKing consists of four divisions: Marketing, Sales,Finance, and Corporate. You divide your network into four subnets, one for each di

技术日志 1825

70-216 Q253 Add the IAS server to the RAS and IAS Servers domain local group

Note: To add the IAS server to a domain:1. Log on to the server using domain administrator credentials.2. Click Start, point to Programs, point to Administrative Tools, and then click ActiveDirectory

技术日志 1759

配置PPPOE路由功能,ADSL简单共享

配置PPPOE路由功能,ADSL简单共享 作者:YeahTech 来源:Yeah!!网络学院 加入时间:2004-10-16  近几年我国的电信事业取得了较大的发展,ISDN、ADSL、LAN等各类宽带接入已变得非常普遍,价格也有较大下降,因此有许多家庭都纷纷接入了宽带,享受宽带信息给我们带来的便利。但是怎么让家中的新旧电脑共享上网呢?一般两台计算机的环境下采用双网卡连接,通过ICS或者SyGat

技术日志 1738
上一篇: WindowsXP中单击右键占大量内存
下一篇: SMS有Network Monitor的网络版
ecrown
博客等级 码龄25年 32粉丝 204原创
评论
成就一亿技术人!
拼手气红包6.0元
还能输入1000个字符
 
 条评论被折叠 查看
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值